Horizon Alert
Summary of the vulnerability and why it matters
This issue in 1C-Bitrix affects the Translate Module, allowing a user with specific permissions to upload and execute code. This could let an attacker gain control of your website.
- Allows code execution.
- Requires elevated permissions.
- Can impact website integrity.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by uploading malicious PHP and `.htaccess` files to a 1C-Bitrix site. This would allow them to execute arbitrary code on the server, provided they have specific 'SOURCE/WRITE' permissions within the Translate Module. The supplier disputes this as a vulnerability, claiming it's intended behavior for high-privileged users.
- Requires specific permissions.
- Targets the Translate Module.
- Uploads executable files.
Live Threat
Current exploitation, exposure, and threat context
The vendor disputes this vulnerability, stating it is intended behavior for users with high privileges to upload translated pages. This significantly limits the realistic attack surface to authenticated users with specific SOURCE/WRITE permissions on the Translate Module. While remote code execution is possible, its exploitation is constrained by these access requirements.
- Limited to authenticated users.
- Vendor claims intended behavior.
- No public exploit or KEV signals.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams should prioritize investigating and securing the 1C-Bitrix Translate Module, especially if it is accessible externally. The vendor disputes the vulnerability, claiming it's intended behavior for privileged users, but the CVSS score indicates a critical risk of remote code execution. Focus on identifying if any user with SOURCE/WRITE permissions for the Translate Module can upload malicious files and restrict these permissions if exploitation is confirmed.
- Review Translate Module permissions.
- Block suspicious file uploads.
- Monitor for unauthorized code execution.